Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareUrsnif | Ursnif has collected files from victim machines, including certificates and cookies. |
| T1012 Query Registry |
MalwareUrsnif | Ursnif has used Reg to query the Registry for installed programs. |
| T1057 Process Discovery |
MalwareUrsnif | Ursnif has gathered information about running processes. |
| T1105 Ingress Tool Transfer |
MalwareUrsnif | Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads. |
| T1112 Modify Registry |
MalwareUrsnif | Ursnif has used Registry modifications as part of its installation routine. |
| T1113 Screen Capture |
MalwareUrsnif | Ursnif has used hooked APIs to take screenshots. |
| T1185 Browser Session Hijacking |
MalwareUrsnif | Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords). |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUrsnif | Ursnif has used Registry Run keys to establish automatic execution at system startup. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.